CentOS 7系统升级后如何防止已删除的YUM仓库被自动重建?
Great question—this is a super common pain point when managing CentOS 7 repos, especially when you need to keep custom repo configurations intact through updates. Let’s break down the most reliable methods to stop those deleted repos from coming back:
If deleted repo files keep reappearing, or you want to protect existing repo configs from being overwritten, use the chattr command to set an immutable attribute on the file:
- First, set up the repo file exactly how you want it (e.g.,
/etc/yum.repos.d/your-custom.repo) - Run this command to lock it:
sudo chattr +i /etc/yum.repos.d/<your-repo-file>.repo
This prevents any user (including root) from modifying, deleting, or renaming the file. If you ever need to edit it later, just remove the attribute with: sudo chattr -i /etc/yum.repos.d/<your-repo-file>.repo
Note: If a system package (like centos-release) tries to replace the repo file during an update, this will block the replacement and trigger a yum warning—but your custom config will stay intact.
Instead of deleting repo files entirely, disable them so yum ignores them, and they won’t get recreated as easily:
- Use yum’s built-in manager to disable a repo:
sudo yum-config-manager --disable <repo-id>
(Runyum repolist allto get the exact ID of the repo you want to disable) - Alternatively, edit the repo file directly and change
enabled=1toenabled=0
If you’re worried about this config being overwritten during updates, pair this with the chattr +i trick from Method 1 to lock the file.
Most default CentOS repo files are provided by packages like centos-release or centos-release-x86_64. When these packages are updated, they’ll overwrite default repo files to their original state. Locking these packages stops that from happening:
- Install the versionlock plugin first:
sudo yum install yum-plugin-versionlock - Check the current version of the package:
rpm -q centos-release - Lock it to prevent updates:
sudo yum versionlock add centos-release
To unlock the package later (if you need to update it), run: sudo yum versionlock delete centos-release
You can reconfigure yum to only read repo files from a custom directory, ignoring the default /etc/yum.repos.d/:
- Edit
/etc/yum.confand add a line like:reposdir=/etc/yum.repos.d/custom-repos - Move all your desired repo files to this new directory, and delete the ones in the default folder
Just be aware that system updates might reset yum.conf, so you should lock this file with chattr +i or pair this with Method 3 to protect the config.
Personally, I recommend combining Method 2 (disable repos) with Method 3 (lock centos-release packages) for the most robust solution—it’s clean, easy to maintain, and avoids potential headaches with immutable files blocking legitimate system updates later on.
内容的提问来源于stack exchange,提问作者Kevin C

